[TLS] Re: PSK identifier (and binder) lengths in the TLS 1.3 outer ECH?
Viktor Dukhovni <[email protected]>
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Aug 14, 2026 at 08:40:49AM -0400, David Benjamin wrote:
> > When there's a broader movement to drop the F5 workaround padding,
> > I'd love to drop that as well.
>
> Oh, that's a good reminder. I had meant to go remove it. Now that
> ClientHellos have ML-KEM key shares, this is moot because they're never in
> the problem range anymore. :-)
>
> I would hope, by now, all the F5s have been updated, but the failure
> condition was a timeout, which made measurements difficult. But happily now
> it doesn't matter. The bookkeeping is indeed a pain.
That's perhaps easier for Chromium if the MLKEM keyshare prediction is
unconditional. In OpenSSL the configuration file and/or application
esttings can tweak keyshare prediction to give a CH size in the F5
danger-zone, and I don't know whether there's any reason to still care.
Are there still somewhere out of view users lovingly maintaining and
getting useful service from unpatched F5's dating back to ~2014?
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]